forked from NVIDIA-AI-Blueprints/vulnerability-analysis
-
Notifications
You must be signed in to change notification settings - Fork 13
APPENG-4467- rpm analyzier mile stone one #222
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
RedTanny
wants to merge
98
commits into
RHEcosystemAppEng:main
Choose a base branch
from
RedTanny:APPENG-4467-Rpm-Checker
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
+17,923
−3,001
Open
Changes from all commits
Commits
Show all changes
98 commits
Select commit
Hold shift + click to select a range
920d528
rpm analyzier mile stone one
RedTanny b5f78d5
start prompt the identify keywords
RedTanny ac1ad18
Identiy sub graph flow
RedTanny fc50fcc
chunk and parse code file and index it to the lexical search
RedTanny 13e2f5f
milestone 1 locate vulnerability place
RedTanny 196508b
locate mile stone 2
RedTanny 4aac49f
verify step 1
RedTanny 0590445
clear labels
RedTanny fb360c3
last changes
RedTanny 994c5a8
generating report for L1 agent
RedTanny 06b9a91
fix L1 report
RedTanny 9c37e84
update prompt
RedTanny d9c7da5
Save changes before change in design
RedTanny 809c9af
redesign: preprocess node
RedTanny 49fb9ad
save work
RedTanny 189dc44
first React agent loop work
RedTanny 1408ea4
improve report for downstream L1
RedTanny cfc9d44
before report change
RedTanny 6cc08a8
fix report
RedTanny 7ff77ed
cleanup and fix bug
RedTanny 9e6102d
add observation logic
RedTanny d793812
observation node part2
RedTanny d1f782e
Integration L2 with flow
RedTanny 91e8ae1
skeleton L2 agent
RedTanny 879d9f0
save cwe-id and add hardening db file
RedTanny ef0d6aa
Imp preprocess data
RedTanny 728406d
force node to code agent
RedTanny e626ccd
L2 Agent build ,before loop
RedTanny 38e580e
not working yet
RedTanny 33bc8e2
E2E - with bugs
RedTanny cefc831
new api schema for rpm checker
RedTanny 9adec40
save before big change
RedTanny 2c0c457
add vulnerability intel
RedTanny da92be1
L2 build agent improvments
RedTanny 9ca31ea
filter binary file
RedTanny a6919ff
fix status of report
RedTanny c06108e
check for package name in cve matches package target
RedTanny 4505954
add Intel calculation of score and reports
RedTanny 4c1842f
clear summary report
RedTanny c10a435
clean report summary executive
RedTanny a30e5f6
update report structure
RedTanny af106d8
report use case upstream find patch to use
RedTanny d91858b
update rebase to fetch patch from github
RedTanny 3720d6d
missing file
RedTanny f484812
send failure to failed node and add url to report
RedTanny 0417b84
grep tool support multi pattern query and fix osv retrive
RedTanny f1dabec
fix extract of tar formats
RedTanny 19c587e
fix tool make them more accurate
RedTanny a064735
fix compile features
RedTanny a79de7e
return default iteration
RedTanny 0974862
add to search ubuntu intel before osv
RedTanny 429bbf9
improve harvest data
RedTanny 9d96d03
not compile use case
RedTanny 1f0c835
fix identification check product before version relation
RedTanny dc6fa0a
add test identifier
RedTanny b44ddda
fix identification report more detail
RedTanny b2b8654
fix tool
RedTanny 2ed7f08
update openai schema
RedTanny 595e79e
Code review: split prompts to a seperated file
RedTanny 09376d7
code review NEVRA
RedTanny 78a0c3a
Support multiple architectures for the same NVR by storing build logs
RedTanny 095c020
phase 1 do not fail flow L2 agent if no build log file
RedTanny eba4ca9
add detail field
RedTanny 64435a2
support kernel packages
RedTanny 3cb21b7
improve report format for checker
RedTanny 1430391
add samba support
RedTanny eb93eed
vulnerability intel sanitizer
RedTanny 12d05cf
add support for external user without vpn need
RedTanny ad59443
fixes prompt
RedTanny 0d251f1
missing pkg for image
RedTanny d2143bc
prune message
RedTanny 76be4af
add cluster config support
RedTanny 9267bef
review fixes
RedTanny 10e888f
comment cleanup
RedTanny 1b1f468
fix
RedTanny ffbe19f
support verify download brew
RedTanny e00f027
disable js avoid errors segmentation , fix identification logic tree …
RedTanny 0bc813d
fix identification and support chromium patch
RedTanny b6c7b81
code review
RedTanny 9583772
update identify tests
RedTanny 45db901
improve performance and LLM conclusion vulnerability
RedTanny d4042fc
fix review clean api
RedTanny c6c47f4
remove deadcode
RedTanny b01ac20
codereview: fix location of import
RedTanny dd88e2c
codeReview: remove wrapper
RedTanny b70ec37
CodeReview fix message
RedTanny 6a93379
clean python cache
RedTanny 7cd7124
clean python cache2
RedTanny 1047d6a
disable tests temp
RedTanny de8c3b6
enable tests
RedTanny 4cd11c7
UI now takes the pack url from artifacts.source_url the source not ne…
RedTanny 4a3e9d8
CodeReview default for ssl verify true
RedTanny c229af7
CodeReview: safe path for readfile
RedTanny 65decc3
CodeReveiw: safe path in _init_
RedTanny d602b77
CodeReview: add documentation for build-essential
RedTanny 9162352
Bug fix find patch in upstream fixed rpm even if no cve number on fil…
RedTanny 935538d
CodeReview update doc for installing bsdtar
RedTanny f7ebf41
fix: handle KeyError in Python parser for third-party packages
RedTanny File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,14 @@ | ||
| # SPDX-FileCopyrightText: Copyright (c) 2025, NVIDIA CORPORATION & AFFILIATES. All rights reserved. | ||
| # SPDX-License-Identifier: Apache-2.0 | ||
| # | ||
| # Licensed under the Apache License, Version 2.0 (the "License"); | ||
| # you may not use this file except in compliance with the License. | ||
| # You may obtain a copy of the License at | ||
| # | ||
| # http://www.apache.org/licenses/LICENSE-2.0 | ||
| # | ||
| # Unless required by applicable law or agreed to in writing, software | ||
| # distributed under the License is distributed on an "AS IS" BASIS, | ||
| # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. | ||
| # See the License for the specific language governing permissions and | ||
| # limitations under the License. |
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.